Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

W32.Spybot.NLX worm on XP


  • Please log in to reply
3 replies to this topic

#1 double_goat

double_goat

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:12:30 PM

Posted 09 July 2005 - 09:15 PM

So...for whatever reason...people have designated me some kind of computer genius :thumbsup:

(My best guess is my ability for deductive reasoning) :flowers:

Nevertheless...a friend of mine has Windows XP
(I personally run Windows '95) :trumpet:
TR/ROOTKIT.L was found on her computer by AntiVir.
This led me to the diagnosis of W32.Spybot.NLX

The only problem is...she claims it has locked up her computer
to the point that the only keys the computer responds to is CTRL-ALT-DEL
and only boots up as far as the System Configuration

Any suggestions? :inlove:

BC AdBot (Login to Remove)

 


#2 stidyup

stidyup

  • Members
  • 641 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:11:30 AM

Posted 11 July 2005 - 03:07 AM

Can you get into safe-mode?

If so run a virus scan from safe mode.

Try running Sysclean you'll also need the virus template file from here lpt***.zip

If your good with the command line also try Sophos Command Line scanner

If you can't get into safe-mode build the Ultimate BootCD 4 Windows this has several AV scanners which should help you to remove the infections from the PC. If you want a working spybot plugin for ubcd4win download from Rapid Share 911 Forum post about the plugin. If this fails at least the ubcd4win will give you read/write access to the NTFS volume to copy data off.

#3 rmm55

rmm55

  • Members
  • 35 posts
  • OFFLINE
  •  
  • Local time:11:30 AM

Posted 11 July 2005 - 11:48 AM

Yes, safe mode is next step. If no success in safe mode you may need to boot from cd and do a repair if your boot sector is damaged.
Roy Mel - YourTechOnline technician
roy@no_spam_yourtechonline.com (remove no_spam_)

#4 double_goat

double_goat
  • Topic Starter

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:12:30 PM

Posted 13 July 2005 - 10:14 PM

:thumbsup: Thanks for the help.

But as many things go when you try to help some people...
she decided it was MY fault for the computer
ever contracting the virus in the first place :flowers:
(by downloading Spybot, AntiVir, and Spyware Blaster)

I explained how I found out that I should have
turned off the system restore device
in Windows XP before we got rid of the infected programs...
that it was most likely repairing them and allowing the worm
to continue to advance through her system.
(I had suggested she leave it alone until I could get to it)

I did have her try to get into Safe Mode...
by using F8, but it wasn't successful.

But she said she had another friend
that most likely could help
and hasn't spoken to me since. :trumpet:

Que sera sera




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users